An update for qemu-kvm-rhev is now available for Red Hat EnterpriseVirtualization.
KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linuxon AMD64 and Intel 64 systems.

The qemu-kvm-rhev package provides the user-spacecomponent for running virtual machines using KVM in environments managed by RedHat Enterprise Virtualization Manager.An out-of-bounds read/write access flaw was found in the way QEMU’s VGAemulation with VESA BIOS Extensions (VBE) support performed read/writeoperations via I/O port methods.

A privileged guest user could use this flaw toexecute arbitrary code on the host with the privileges of the host’s QEMUprocess. (CVE-2016-3710)

For details on how to apply this update, which includes the changes described inthis advisory, refer to: installing this update, shut down all running virtual machines. Once allvirtual machines have shut down, start them again for this update to takeeffect.
Updated packages
Red Hat Enterprise Virtualization 3

